When the Menu Sat on Top of the Test Object: The Ford 26V489 Rearview-Camera Recall Through an FMVSS 111 Default-View and ISO 26262-9 Lens

A driver taps the front camera button while sitting still, opens the Views menu, picks nothing, then shifts into Reverse. The rearview image comes up exactly as designed. So does the menu, sitting on top of it, covering one of the seven cylinders NHTSA puts behind the truck to decide whether the vehicle is legal. Nothing crashed. Nothing timed out. Every component did its job. The composite was still wrong.

I have written about display failures on this blog before, and I keep coming back because the automotive industry has never really decided who owns the pixel. It owns the camera. It owns the bus. It owns the module. It does not own the photons that arrive at the driver's eye, and every one of these recalls lives in that gap.


1. The public record

NHTSA campaign 26V489, filed July 28, 2026, Ford reference 26C37. Component: BACK OVER PREVENTION. Population: 47,587 vehicles — 24,408 model-year 2021–2023 F-150 and 23,179 model-year 2023–2026 F-250 Super Duty, all with the 8-inch SYNC 4 landscape display and the 360-degree camera system. Estimated percentage with the defect: 100%. (NHTSA recall 26V489; Pickup Truck +SUV Talk, August 5, 2026)

Ford's own Part 573 language is unusually clean, so I will quote it rather than paraphrase:

"If a customer leaves the camera 'Views' menu open on the SYNC 4 screen and shifts the vehicle into Reverse, the menu overlay does not auto-dismiss. As a result, the menu persists on the screen and will remain on until either (a) the user selects a view or closes the menu, or (b) the vehicle is shifted to Drive and speed exceeds 5 mph. If tested according to FMVSS No. 111, the menu overlay on these vehicles will partially cover certain test objects in the Rear View Camera (RVC) image."

Cause: APIM software prior to version 2.4.12. Warning to the driver that this is happening: "None." Remedy: OTA or dealer flash to 2.4.12 or above. Ford is aware of no crashes, no injuries, no warranty claims, and no Vehicle Owner Questionnaires on the condition.

The chronology is worth reading as a process record. On May 14, 2026, the concern reached Ford's Critical Concern Review Group. ADAS engineering demonstrated the trigger is not random — it is a deterministic input sequence: activate a camera view while not in Reverse, open the Views menu, select nothing, shift to Reverse. Through late May and June, CCRG ran a read-across of every SYNC 4 line against "every build configuration for display size, screen orientation, and available camera views," and found that only two configurations — 8-inch landscape plus 360 camera — pushed the overlay far enough to obscure a required test object under NHTSA Laboratory Test Procedure TP-111V-01, Section C (Default View). Ford reviewed the finding with NHTSA's Office of Vehicle Safety Compliance on July 8, and the Field Review Committee approved the action on July 21.

That is competent engineering after the fact. It is also the fifth time in roughly two years that Ford has told NHTSA the rear image is not what the standard requires — each time for a completely different reason.

| Action | Date | Population | Mechanism | Clause stressed | | --- | --- | --- | --- | --- | | 2020 camera recall (subject of NHTSA probe opened Aug 3, 2021) | 2020 | 620,000+ | Insufficient PCB electrical conductivity; intermittent or inoperative camera | Field of view, availability | | 25V312 | May 2025 | 2021–2022 Bronco, 8-in SYNC | Vehicles repaired incorrectly under a prior recall; image still displayed after the backing event ended | S6.2.4 Linger time | | 26V124 (Ford 26S09) | Mar 6, 2026 | 849,310 Bronco / Edge | APIM reaches 105 °C and enters thermal shutdown for up to five minutes; no image in Reverse | S6.2.1, S6.2.3 | | 26V123 | Mar 2026 | 889,950 Escape / Corsair / Aviator / Explorer | SYNC image flipped or inverted after an ignition cycle — image, buttons and guidelines all mirrored | S6.2.1 geometry | | 26V489 (Ford 26C37) | Jul 28, 2026 | 47,587 F-150 / F-250 | Views menu overlay persists into Reverse, covering a required test object | S6.2.1, S6.2.6 Default view |

Sources for the rows above: Fox Business, March 9, 2026; autoevolution on the APIM thermal shutdown; Ford Authority on 26S09; NHTSA 25V312 acknowledgement.

And the context that makes this more than a run of bad luck: on November 13, 2024, Ford entered a three-year consent order with NHTSA carrying a $165 million civil penalty — $65M cash, $55M held in abeyance, $45M directed at advanced data analytics, a multi-modal imaging lab for low-voltage electronics, and VIN-based traceability. The subject of that consent order was the timeliness of a rearview camera recall. Ford has now filed three more rear-visibility noncompliance actions while operating under it. (NHTSA press release; Ford 8-K, November 13, 2024)

The money bought data analytics and an imaging lab. Neither of those catches a menu drawn on the wrong layer.


2. The standards lens

2.1 FMVSS 111 — the clause that actually bites is Default view, not Field of view

Ford's 573 cites the field-of-view requirement at S5.5.1. For a truck, the operative text lives at S6.2.1 — the wording is duplicated verbatim between the passenger-car block (S5.5) and the MPV/truck/bus block (S6.2), so nothing turns on it substantively. What does turn on it is which sub-clause the failure violates.

The physical requirement is concrete. Seven right circular cylinders, each 0.8 m high and 0.3 m in diameter, placed behind the vehicle: F and G at 0.3 m aft of the rear bumper plane, D and E at 3.05 m, A, B and C at 6.1 m, with the outboard pairs on longitudinal planes 1.52 m either side of centreline. The rearview image must include the full width and height of A through E, and at least a 150 mm wide strip of F and G. Objects A, B and C must average not less than 5 minutes of arc of subtended visual angle, and no single one may fall below 3 minutes of arc. (49 CFR 571.111, S14.1.3–S14.1.4)

Then the sub-clauses that govern behaviour rather than optics:

S6.2.6 is a state-restoration requirement, and it is the one 26V489 breaks. The regulator anticipated exactly this: drivers will fiddle with the view, and the system must forget all of it and come back clean every single time the selector hits R. Ford's HMI honours that for the camera view but not for the overlay stack — the view resets, the menu does not.

Note also the definition of backing event in S4: it starts when the selector goes to reverse and ends, at the manufacturer's choosing, at 10 mph, 10 metres travelled, or 10 seconds of forward motion. Ford's dismiss condition is "Drive and speed exceeds 5 mph." That is inside the regulatory window, so it is not itself a violation — but it tells you the dismiss logic was written against a drive-cycle heuristic rather than against the defined backing event. When your teardown condition and the standard's event boundary are written in different vocabularies, you are one refactor away from a linger-time finding as well. Which is what 25V312 already was.

2.2 ISO 26262-3 §7 — the HARA row that would have changed the architecture

Rear visibility is treated across the industry as a compliance function, not a safety function. FMVSS 111 says produce the image; the display sits in the infotainment domain; the infotainment domain is QM; done. Nobody runs the row.

Run it.

| Field | Entry | | --- | --- | | Item | Rear Visibility System (RVC camera, APIM, centre display, compositor) | | Operating situation | Reverse manoeuvre from a driveway or parking bay, residential or retail environment, vulnerable road users present, dry, daylight | | Malfunctioning behaviour (guide word: incorrect) | Rearview image is presented, but part of the mandated rear field of view is occluded, mirrored, or geometrically transformed | | Hazardous event | Driver reverses into a vulnerable road user standing in the occluded sector of the mandated field of view | | Severity | S3 — backover of a pedestrian, life-threatening to fatal | | Exposure | E4 — reversing from a parking space or driveway is a routine, high-frequency manoeuvre | | Controllability | C3 — the driver has no cue that the sector is occluded; the system reports normal operation and the 573 records the driver warning as "None" | | ASIL | C | | Safety goal | SG-RV-01 — Prevent presentation of a rearview image in which any portion of the mandated rear field of view is occluded, mirrored, or otherwise transformed, for the duration of a backing event |

The obvious objection is controllability. Ford would argue, and many OEMs would agree, that the driver retains mirrors and a head check, so this is C2 or even C1. Fine — argue it. But notice what the table does to you at S3 and E4: C3 gives ASIL C, C2 gives ASIL B, and C1 still gives ASIL A. There is no honest path to QM at S3/E4. To land on QM you have to argue E3 and C1 together — that reversing near pedestrians is only of medium exposure and that over 99% of drivers routinely avoid a hazard they cannot see. On a full-size Super Duty, whose rear blind zone for a shorter driver runs to tens of feet, that second half is not defensible.

So the whole rendering chain in these trucks is QM, and the row that would have said otherwise was never written — because the function was filed under "regulatory compliance" instead of "hazard."

2.3 ISO 26262-9 §6 and ISO 26262-6 Annex D — the shared resource is the framebuffer

This is the part I want HMI teams to internalise. ISO 26262-9 Clause 6 governs the coexistence of elements: when a sub-element of lower or no ASIL shares an element with a safety-related sub-element, the lower one inherits the higher ASIL unless freedom from interference is demonstrated. ISO 26262-6 Annex D enumerates the interference classes you must argue against — timing and execution, memory, and exchange of information.

Everyone in this industry has internalised memory partitioning and MPU configuration. Almost nobody treats the display composite as a shared resource in the same sense — and it is one. The framebuffer, the layer stack, and the compositor's z-order table are a shared resource through which a QM element (a settings menu) can corrupt the output of a safety-relevant element (the rear image) without touching a single byte of its memory or stealing a single microsecond of its execution time. The corruption happens downstream of both, in the composite.

26V489 is a textbook freedom-from-interference violation on a resource class that ISO 26262's own annex does not name explicitly. The QM menu was composited above the safety-relevant surface, and no mechanism existed to stop it. Then look at the other four recalls in the table above and notice they are all interference or integrity failures on the same output path, at different layers:

Five layers, five recalls, one unwritten safety goal.

2.4 IATF 16949 and 8D — the read-across keeps working and the recurrence keeps happening

Ford's CCRG process did its job in June 2026: a genuine read-across across every SYNC 4 configuration, including display size and orientation, evaluated against S5.5.1. That is a real D5/D6. But 8D D7 — Prevent Recurrence asks a different question, and it is the one the record says nobody answered: what systemic control keeps the rear image compliant regardless of which layer breaks next?

Every corrective action in this chain was scoped to its own root cause. Fix the PCB. Fix the thermal software strategy. Fix the flip. Fix the z-order. Fix the linger. None of them is wrong. All of them are downstream of a requirement that does not exist.


3. A worked snippet

3.1 Fault tree — the top event nobody wrote

TOP  Mandated rear field of view not correctly presented
     to the driver during a backing event
      |
      +--[ OR ]
         |
         +-- G1  Image not acquired at the sensor
         |       BE1.1  RVC PCB conductivity loss  [2020 recall]
         |       BE1.2  Lens obscuration / water ingress
         |
         +-- G2  Image acquired, host unavailable
         |       BE2.1  APIM thermal shutdown, up to 105 C,
         |              blackout up to 5 min      [26V124]
         |       BE2.2  Host reset during backing event
         |
         +-- G3  Image rendered with wrong geometry
         |       BE3.1  Framebuffer mirrored / inverted after
         |              ignition cycle; guidelines follow  [26V123]
         |       BE3.2  Aspect or crop error reduces FOV below
         |              the S6.2.1 envelope
         |
         +-- G4  Image rendered correctly, then occluded
         |       BE4.1  QM overlay composited above the RVC
         |              surface and not dismissed on R   [26V489]
         |       BE4.2  Notification / popup drawn over the image
         |
         +-- G5  Image presented outside the required window
                 BE5.1  Image persists after backing event ends
                        (linger)                          [25V312]
                 BE5.2  Image later than 2.0 s from selector to R

Every basic event in that tree except BE1.2, BE2.2, BE3.2 and BE4.2 is a real, filed, public defect. The tree was reconstructable from the recall record. It was reconstructable from a whiteboard in 2018.

3.2 The missing cell in the HMI state machine

| Pre-existing HMI state | Selector to R | Specified behaviour | Implemented behaviour | | --- | --- | --- | --- | | Home screen | R | Show default RVC view | Correct | | Navigation full screen | R | Show default RVC view | Correct | | Front camera view active | R | Show default RVC view | Correct — view resets | | Front camera view active + Views menu open, no selection | R | Show default RVC view, dismiss overlay | Overlay persists | | Views menu open from home screen | R | Show default RVC view, dismiss overlay | Overlay persists, minimal occlusion |

The specification column exists in FMVSS 111 S6.2.6 as a single sentence covering all rows. The implementation handled the view as state and the overlay as decoration. That distinction is invisible in a requirements document and fatal in a compositor.

3.3 DFMEA row, AIAG-VDA 2019

| Field | Before action | After action | | --- | --- | --- | | Function | Present a compliant rearview image on the centre display for the duration of a backing event | — | | Failure mode | Camera Views menu overlay persists into Reverse, occluding test object D or F | — | | Effect (vehicle level) | Mandated FOV partially lost; FMVSS 111 S6.2.1 / S6.2.6 noncompliance; backover of an occluded pedestrian | — | | S | 10 (affects safe operation and road users; S9 alone if scored purely as regulatory noncompliance) | 10 | | Prevention control | HMI specification review; no requirement on overlay priority during a backing event | Compositor z-order enforced in hardware layer config; RV-102 | | O | 6 — deterministic given a plausible customer input sequence | 2 | | Detection control | HMI functional test suite; FMVSS 111 bench test executed from default HMI state only | Rendered-frame fiducial monitor; full state cross-product on HIL; RV-103 | | D | 7 | 2 | | Action Priority | High | Medium |

Worth saying plainly: at S9–S10 the AIAG-VDA lookup will not hand you a Low AP until occurrence reaches 1. You get to O=1 by making the failure structurally impossible — a fixed-priority hardware compositor plane the application layer cannot address — not by writing a better dismiss handler.


4. Derived requirements (excerpt)

RV-101 — Default view restoration. On transition of the direction selector to Reverse, the rear visibility system shall restore the compliant default rearview image and dismiss every non-safety overlay within 300 ms, such that a fully compliant image per FMVSS 111 S6.2.1 and S6.2.2 is presented within 2.0 s of the start of the backing event. Verification: HIL sweep over the complete cross-product of pre-existing HMI states, display sizes, orientations, and camera-system variants. Acceptance: 100% of enumerated states produce a compliant image; zero persistent overlays.

RV-102 — Compositor priority is a hardware property. No display layer allocated an ASIL lower than that of SG-RV-01 shall be composited above the rearview image surface during a backing event. Priority shall be enforced in display-controller layer configuration locked at initialisation, not in application logic. Verification: register inspection plus fault injection in which an application element attempts to raise its own layer above the RVC surface. Acceptance: attempt rejected; at least one diagnostic event logged; RVC surface remains topmost.

RV-103 — Verify the rendered frame, not the source frame. During a backing event the system shall verify the composited output, sampling at not less than 5 Hz, confirming that four registered fiducial regions corresponding to the corners of the mandated field of view are present, correctly oriented, and unoccluded. Detected failure shall escalate per RV-105 within 500 ms. Verification: injected occlusion, mirror, and crop faults at the composite stage. Acceptance: detection of every injected fault within 500 ms; false-positive rate under 1 per 10,000 backing events.

RV-104 — Availability of the presentation path under thermal load. The display path carrying the rearview image shall remain available across the full qualified cabin thermal profile. Any thermal-protection action shall not remove the rearview image, and margin from the qualification limit to any shutdown threshold on that path shall be at least 15 °C. Verification: thermal chamber soak at the qualification limit with sustained backing events, instrumented board and junction temperatures. Acceptance: zero image loss; measured margin at or above 15 °C.

RV-105 — No silent degradation. Where a compliant rearview image cannot be presented, the system shall annunciate loss of rear visibility to the driver within 500 ms of detection, using a distinct, non-dismissible indication, in preference to presenting a degraded, occluded, or transformed image. Verification: fault injection against every branch of the RV fault tree. Acceptance: annunciation on 100% of injected faults; no case in which a non-compliant image is presented without annunciation.

RV-105 is the one I would fight for. Ford's 573 records the driver warning as "None" — which is honest, and also the whole problem. A system that cannot tell the difference between a good image and a covered one cannot warn you about either.


5. What the headline really tells us

The headline says Ford recalled 47,000 trucks because a menu did not close. The engineering record says something more durable: five independent defects, at five different layers of one display pipeline, all produced the same top event, because no requirement was ever written about the top event itself.

Requirements were written about the camera. About the module. About the software version. About response time. Each of those requirements was met by the component that owned it, in every one of these recalls except its own. What was never written is the requirement that owns the output: the pixels presented to the driver during a backing event shall constitute the mandated field of view, and the system shall know whether they do.

That requirement is not exotic. FMVSS 111 S6.2.6 has been in force since May 2018 and it is a state-restoration clause — it already tells you the rear image is a state to be re-established, not a stream to be forwarded. ISO 26262-9 Clause 6 already tells you what to do when a QM element shares a resource with a safety-relevant one. ISO 26262-6 Annex D already tells you to enumerate interference paths, and the fact that it lists memory, timing, and information exchange rather than "output composition" is an argument for extending your analysis, not for skipping it.

NHTSA spent $165 million of Ford's money on data analytics, an imaging lab, and VIN traceability. Every one of those is a detection investment — better at finding the defect after it ships. The missing artifact is upstream of all of it: one HARA row, one safety goal, and a monitor that looks at the finished frame instead of the source.

A camera that works, a module that works, and software that works can still add up to a driver who cannot see the child behind the truck. Compliance is a property of the composite. Somebody has to own it.


Sources

Jherrod Thomas, The Lion of Functional Safety™